AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
Must ComplyRegulationUSHigh risk

Promoting Advanced Artificial Intelligence Innovation and Security

Issued by

White House (Executive Office of the President)

liveEffective 2026-06-28PAIAISVerified July 2026
Official document →

This presidential action establishes a classified benchmarking process to evaluate the advanced cyber capabilities of frontier AI models and creates a designation process for 'covered frontier models' that triggers federal pre-release access requirements. It applies primarily to AI developers building or deploying large-scale frontier models with potential cybersecurity implications. Designated developers must provide the federal government with 30-day advance access to covered models before public or commercial release, under strict confidentiality and cybersecurity protocols.

Applies To

Large enterpriseAI developer

Overview

Issued on June 28, 2026, this presidential action directs the establishment of a classified framework through which the federal government assesses whether advanced AI models meet the threshold for designation as 'covered frontier models' based on their potential cyber capabilities. Developers may voluntarily engage the government for a model designation determination, and those whose models are designated must provide 30 days of pre-release access to authorized federal evaluators. The benchmarking process is classified, meaning developers will be subject to strict confidentiality requirements and must maintain cybersecurity controls commensurate with handling sensitive government evaluations. The order is primarily administered with NSA involvement for the cyber assessment function, and compliance obligations attach at the point of model designation rather than universally to all AI developers. Enforcement mechanisms and penalties for non-compliance with pre-release access requirements are not fully disclosed in public-facing materials due to the classified nature of portions of the order. The action intersects with existing enterprise obligations around model risk management, incident response, and third-party security requirements for any organization developing or deploying frontier-scale AI systems.

Key Requirements

  • Developers of advanced AI models must engage the federal government to determine whether their model qualifies as a 'covered frontier model' under classified benchmarking criteria.
  • Developers of designated covered frontier models must provide federal authorities with 30-day pre-release access before any public or commercial deployment.
  • Pre-release access must be conducted under strict confidentiality agreements and cybersecurity controls meeting federal standards.
  • Developers must implement and maintain cybersecurity protections sufficient to safeguard model weights and evaluation materials during the federal assessment period.
  • The designation and benchmarking process involves classified components; developers handling related materials may be subject to federal information security and clearance requirements.
  • Non-compliance consequences for failure to provide pre-release access or maintain required confidentiality are subject to federal enforcement authority, with specific penalties not publicly disclosed.
  • The order explicitly prohibits any mandatory preclearance regime for frontier AI developers; participation in the advance-access program remains voluntary.

What Your Organization Must Do

  • Audit your AI development pipeline to identify any models that may meet frontier-scale thresholds for cyber capability and could be subject to designation review.
  • Establish an internal process to proactively engage federal authorities for model designation determinations before finalizing release timelines for advanced models.
  • Build a minimum 30-day federal review buffer into all release planning schedules for any model that could plausibly be designated as a covered frontier model.
  • Implement and document cybersecurity controls for model weights and evaluation environments that meet federal standards in anticipation of pre-release access requests.
  • Review and update vendor and partner agreements to ensure any third-party developers contributing to frontier model development understand and can comply with pre-release access obligations.
  • Brief legal counsel and the CISO on the classified components of this order to assess whether personnel with security clearances need to be involved in compliance workflows.

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Frequently Asked Questions

Does PAIAIS require all AI developers to submit models for federal review before release?
No. The pre-release access obligation only attaches after a model is formally designated as a covered frontier model. Participation in the designation determination process is voluntary, and there is no mandatory preclearance regime for all frontier AI developers.
What triggers the 30-day pre-release access requirement under PAIAIS?
The requirement is triggered by a formal designation of a model as a covered frontier model following classified benchmarking by federal authorities. Developers should build at least a 30-day buffer into release schedules for any model that could plausibly meet the cyber capability thresholds.
Which federal agency leads the cybersecurity assessment under PAIAIS?
The NSA plays a primary role in the cyber assessment function. Because portions of the benchmarking framework are classified, developers engaging in the designation process may need personnel with appropriate security clearances involved in compliance workflows.
What cybersecurity controls must developers implement to comply with PAIAIS pre-release access requirements?
Developers must maintain cybersecurity protections for model weights and evaluation materials that meet federal standards. Specific control requirements are tied to confidentiality agreements executed during the pre-release access period, and the classified nature of the process means full requirements are not publicly disclosed.
What are the penalties for failing to provide pre-release access under PAIAIS?
Specific penalties are not publicly disclosed due to the classified components of the order. Enforcement authority rests with federal agencies, so legal counsel should assess exposure based on the organization's designation status and any agreements signed during the review process.
How does PAIAIS interact with existing model risk management and third-party security obligations?
PAIAIS layered onto existing enterprise obligations around model risk management, incident response, and third-party security. Vendor and partner agreements should be reviewed to confirm that third-party contributors to frontier model development can meet pre-release access and confidentiality requirements if a designation is triggered.